Subject: bin/11151: apmd(8) local domain socket permissions not really sensical
To: None <gnats-bugs@gnats.netbsd.org>
From: Klaus Klein <kleink@uni-trier.de>
List: netbsd-bugs
Date: 10/06/2000 00:59:19
>Number:         11151
>Category:       bin
>Synopsis:       apmd(8) local domain socket permissions not really sensical
>Confidential:   no
>Severity:       non-critical
>Priority:       low
>Responsible:    bin-bug-people
>State:          open
>Class:          change-request
>Submitter-Id:   net
>Arrival-Date:   Fri Oct 06 00:59:00 PDT 2000
>Closed-Date:
>Last-Modified:
>Originator:     Klaus Klein
>Release:        today's
>Organization:
Frobozz Magic Standards Company
>Environment:
i386

>Description:
	When invoked without a modification via the command line, access
	to apmd(8)'s local domain control socket is restricted to the
	superuser and members of group wheel.

	It's not clear to me why these file permissions should restrict
	access in a way different from that of shutdown(8), which permit
	members of group `operator' to shutdown/halt/power-down the machine.

>How-To-Repeat:
	ls -l /var/run/apmdev.  Scratch head.

>Fix:
	Change apmd(8) to try to determine group `operator' first and
	set the socket's group accordingly; otherwise fall back to the
	current behaviour.

>Release-Note:
>Audit-Trail:
>Unformatted: